Payflex Payment Gateway
Payflex Payment Gateway has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2024; all 2 are fixed as of September 2026. Their average CVSS score is 5.7, and the most serious one scores 6.1 out of 10. 2024 was the busiest year with 2 disclosures.
The most common weakness is Missing Authorization, behind 1 of the records (50%). Other recurring categories include Open Redirect.
Every one of the 2 issues recorded for Payflex Payment Gateway has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Payflex Payment Gateway is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2024-47646Payflex Payment Gateway <= 2.6.1 - Open Redirect
Read the full analysisVulnerability Records

Payflex Payment Gateway
Author
tomlister
The Payflex extension for WooCommerce enables you to accept payments in installments via one of South Africa’s most popular payment gateways. Why choose Payflex? Give your customers a better way to pay and they’ll have more reason to buy.Payflex is proven to increase sales conversion rates and average order values.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C